Cyber Essentials is the UK government-backed scheme that certifies your organisation has the basic controls in place to defend against common cyber attacks. This guide walks you through preparation from first gap check to certification submission.
Cyber Essentials is built around five technical controls. Every question in the self-assessment maps back to one of them. Knowing what each area covers means you can audit yourself before the assessor does.
Boundary firewalls and internet gateways must be configured to block unapproved access. All devices must have a personal firewall active.
Remove or disable default accounts, change default passwords, and disable unnecessary services and software.
Only authorised individuals should have accounts. Standard user accounts for day-to-day work; admin rights only when needed, from a separate account.
Anti-malware software installed, active, and kept up to date — or application allowlisting to prevent execution of unauthorised software.
Operating systems, firmware, and software patched or updated within 14 days of a high/critical update being released.
What they look for
Assessors don't test your knowledge of the five areas — they test your implementation. Have a document or screenshot showing your firewall rules, your user account list with MFA status, your anti-malware version and last update date, and a log of recent patches. These are the four artefacts most commonly checked at the start of a CE+ technical assessment.
Before you touch any configuration, assess your current state. A readiness check tells you which control areas you're close on and which need significant work — so you don't waste time patching things that aren't the problem.
What they look for
Before paying for certification, get a scored gap report. Assessors see many organisations arrive at CE+ having only partially implemented controls — particularly around admin account separation and patch management on third-party software like browsers and Office.
Work through your findings by severity. Typical quick wins that many small businesses can fix in a day:
Microsoft 365, Google Workspace, cloud portals. This single change addresses one of the most common CE+ failure points.
Check every device for pending OS and software updates. Enable automatic updates where possible. Remove end-of-life software.
List every account with admin rights. Remove rights from anyone who doesn't need them day-to-day. Create separate admin accounts for those who do.
Check that no inbound rules allow access from any IP to any port unnecessarily. The default should be deny — allow only what is specifically needed.
What they look for
MFA on admin and cloud accounts is the single most commonly failed CE+ control. Your assessor will verify this directly — either by reviewing screenshots of your admin portal or by attempting to log in without MFA. If any admin or internet-facing account lacks MFA, you will fail at this step.
Cyber Essentials and Cyber Essentials Plus are both valid certifications — but they differ in how they're verified.
You complete an online questionnaire about your controls. A certifying body reviews your answers. No technical test — but your answers must be accurate.
All of CE, plus a certifying body carries out an external vulnerability scan and an internal assessment of your devices. More rigorous, and required by some contracts.
What they look for
For CE+, the certifying body performs an external vulnerability scan of all your internet-facing IPs and an internal assessment of a sample of in-scope devices. They will check OS patch level, anti-malware status, and firewall configuration directly — you cannot pass CE+ by claiming controls are in place.
Use the Fortify portal to track each control area, attach evidence (screenshots, configuration exports, policy documents), and generate a management summary. When the assessor asks, your evidence is already organised.
What they look for
Your evidence pack for the assessor should include: scope statement, firewall policy with current rule set, screenshot of MFA on all admin accounts, anti-malware dashboard showing active protection, and a patch activity log. Missing any one of these will slow the audit significantly.
Where people go wrong
Separating admin from user accounts only for the assessment, then reverting
CE+ includes surveillance audits. Assessors also check account creation dates — accounts created immediately before the audit raise questions.
MFA enabled on personal accounts but not admin accounts
The most common single point of failure at Stage 2. Admin accounts, service accounts, and cloud platform admin portals all need MFA — not just Microsoft 365 or Gmail.
End-of-life software found on a single device
One device running Windows 7, an unsupported browser version, or end-of-support Office fails the scope. The entire in-scope environment must meet the standard, not a representative sample.
Scope defined too narrowly to exclude problematic systems
Assessors expand scope if it appears designed to exclude difficult systems. If customer data flows through a system, it is in scope. Trying to leave out legacy servers or old laptops will not work.
Patching desktops but ignoring server OS and third-party software
Patch management must cover all in-scope software: OS, firmware, browsers, Office, plugins, and any server software. A patched Windows 10 with an outdated Chrome installation fails the control.
How long does Cyber Essentials preparation take?
For an organisation with no existing controls in place, 4–8 weeks is realistic for CE and 8–12 weeks for CE+. For businesses with reasonable IT hygiene already, preparation for CE can take as little as 1–2 weeks.
What's the cost of Cyber Essentials certification?
CE self-assessment certification costs from around £300 for small organisations through IASME-accredited bodies. CE+ includes a technical audit and typically costs £1,000–£3,000 depending on the size and complexity of your environment.
Do we need Cyber Essentials or Cyber Essentials Plus?
CE is sufficient for most contract requirements and is the mandatory requirement for UK government contracts handling personal data. CE+ is required by some NHS contracts and larger enterprise procurement processes. Check your specific requirements.
What happens if we fail the CE+ technical assessment?
You'll receive a report of the findings. Most certifying bodies allow a remediation period (typically 30 days) and a re-test. The Fortify portal tracks your open CE findings so you know what needs fixing before re-submission.
Fortify's free Cyber Essentials readiness check walks you through all five control areas and produces a scored gap report in 10 minutes — no account required.
Latest on this topic